Privacy Policy
How EzyCore handles personal data — what we collect, why we process it, and what you can ask us to do with it.
Last updated: 29 July 2026
Draft — this document has not yet been reviewed by a lawyer and is not final. It describes our current practice in good faith, but please treat it as provisional until this notice is removed.
1. Scope and our role
This policy explains how EzyCore handles personal data across this website, the EzyCore application, and the online stores our merchants publish.
Two roles matter here. For the data of merchants and their staff — the people who sign up and use a workspace — EzyCore is the controller, and this policy applies directly. For the data of shoppers buying from a merchant's online store, the merchant is the controller and EzyCore is their processor: we handle that data on the merchant's instructions, and the merchant's own privacy notice governs it.
2. What we collect
We collect:
- Account data — name, email, phone, business name, and the workspace settings you choose.
- Workspace content — the products, customers, suppliers, orders, documents and files you enter or upload.
- Billing data — your plan, billing interval, invoices and payment status. Card and mobile-wallet details go directly to our payment processors; we never receive or store them.
- Technical data — IP address, browser and device information, and log records of requests to the service.
- Enquiry data — whatever you send us by email, by phone, or through the contact form on this site.
3. How we use it
We do not sell personal data, and we do not use your workspace content to train models or to build products for other customers.
We use personal data to:
- create and operate your workspace, and authenticate you
- process subscriptions, payments and renewals
- provide support and answer your enquiries
- keep the platform secure — detecting abuse, investigating incidents, maintaining audit trails
- improve the product, using aggregated or de-identified usage patterns
- send service messages about billing, security or material changes
- send occasional product news and offers by email — every such message carries an unsubscribe link, and opting out never affects the service messages above
4. Legal basis
Where data-protection law requires a legal basis, we rely on performance of our contract with you (running your workspace and billing you), our legitimate interests (securing the platform, preventing abuse, improving the product), your consent where we ask for it, and compliance with legal obligations such as tax and accounting record-keeping.
EzyCore is operated from Bangladesh and is intended for businesses trading there, so Bangladeshi law governs how we handle personal data. We do not currently market or offer the service in the EU or the UK, so the GDPR is not in scope. If that changes we will update this policy and put the additional protections those regimes require in place before we begin.
5. Payments
Subscription payments are handled by our payment processors — Stripe for card payments and SSLCommerz for local Bangladeshi methods including bKash. They receive the payment details you enter and process them under their own privacy policies. EzyCore stores only the outcome: the plan, the interval, whether payment succeeded, and the invoice record.
Payments your own shoppers make on your storefront are settled between you and them under the methods you have enabled — currently cash on delivery and bank transfer.
6. Cookies and local storage
We use cookies and browser local storage for what the product cannot work without: keeping you signed in, remembering your active location, and holding a shopper's cart. This marketing site uses only what is needed to serve the page and remember your language.
We do not use analytics, advertising or third-party tracking cookies anywhere — not on this site, not in the application, and not on the storefronts our merchants publish. There is nothing to consent to and no cookie banner to dismiss. If we ever add such cookies we will ask for your consent first and update this policy.
7. Sharing and sub-processors
We share personal data only with the service providers who help us run EzyCore, and only as far as each needs it. Where a merchant enables them, courier services also receive the delivery addresses they need in order to fulfil orders.
We may also disclose data where the law requires it, or to protect our rights, our customers, or the safety of others. If EzyCore is ever part of a merger or acquisition, data may transfer as part of that, and we will give notice first.
Our sub-processors today are:
- MongoDB Atlas — database hosting for all workspace data
- Cloudflare — delivery of this site and of merchant storefronts, and object storage for the images and files you upload
- Resend — delivery of transactional email such as invitations, password resets and billing notices
- Stripe — card payment processing
- SSLCommerz — local Bangladeshi payment methods, including bKash
- Web3Forms — delivery of messages sent through the contact form on our marketing site
- Google and Meta — only where you choose to sign in with a Google or Facebook account
8. Security
Workspaces are tenant-isolated: no business can see another's data. Access within a workspace is governed by the roles and permissions its owner controls. Data is encrypted in transit, credentials are stored hashed, and access to production systems is restricted.
No system is perfectly secure. If a breach affects your personal data we will notify you and, where required, the relevant authority, without undue delay.
9. How long we keep it
We keep workspace data for as long as your subscription is active. After it ends we retain the workspace for a limited period so you can reactivate or export it, and then delete it.
Some records — invoices, payment records and other financial documents — are kept longer where tax and accounting law requires.
In concrete terms: workspace data is deleted 90 days after a subscription ends, and invoices, payment records and other financial documents are kept for at least six years, as company and tax law in Bangladesh requires. That obligation is why those financial records outlive the workspace they came from.
10. Your rights
Subject to local law you can ask us for a copy of your personal data, to correct it, to delete it, to restrict or object to how we use it, or to provide it in a portable format. Most of this you can do yourself from your workspace settings; for anything else, email us.
If you are a shopper on a merchant's store, send your request to that merchant — they control that data, and we will help them respond.
You may also complain to your local data-protection authority.
11. International transfers
EzyCore is operated from Bangladesh, and our infrastructure providers may process data in other countries. Where data crosses a border we take steps to keep it protected to the standard described here.
Workspace data and its backups are held on infrastructure operated by MongoDB Atlas and Cloudflare, both of which run data centres in a number of countries. Because we do not currently serve EU or UK customers, we do not rely on the transfer mechanisms those regimes require; if we begin serving them we will put an appropriate mechanism in place and describe it here.
12. Children
EzyCore is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us personal data, contact us and we will delete it.
13. Changes to this policy
We will update this policy as the product and the law change. Material changes will be notified in the app or by email before they take effect, and the date at the top of this page is always the date of the current version.
14. Contact
The controller is EzyCore, a sole proprietorship registered in Bangladesh under trade licence no. 26291101519000229, issued by Azimnagar Union Parishad, Bhanga, Faridpur. Our registered postal address is available on request.
For any privacy question or request, email [email protected] or call +880 1915-555256.
We have not appointed a data protection officer or a local representative — no law that currently applies to us requires one. Privacy questions and requests go to the contact above, and we answer them ourselves.